D487 - SECURE SOFTWARE DESIGN ACTUAL EXAM QUESTIONS AND
D487: Secure Software Design
ANSWERS (VERIFIED AND WELL ELABORATED ANSWERS) LATEST
Study online at https://quizlet.com/_hbb0ux
UPDATE 2025/2026
1. Building Security A study of real-world software security initiatives organized so that you can deter-
In Maturity Mod- mine where you stand with your software security initiative and how to evolve your
el (BSIMM) efforts over time
2. SAMM offers a roadmap and a well-defined maturity model for secure software develop-
ment and deployment, along with useful tools for self-assessment and planning.
3. Core OpenSAMM Governance
activities Construction
Verification
Deployment
4. static analysis Source code of an application is reviewed manually or with automatic tools without
running the code
5. dynamic analysis Analysis and testing of a program occurs while it is being executed or run
6. Fuzzing Injection of randomized data into a software program in an attempt to find system
failures, memory leaks, error handling issues, and improper input validation
7. OWASP ZAP -Open-source web application security scanner-Can be used as a proxy to manip-
ulate traffic running through it (even https)
8. ISO/IEC 27001 Specifies requirements for establishing, implementing, operating, monitoring,
reviewing, maintaining and improving a documented information security man-
agement system
9. ISO/IEC 17799 ISO/EIC is a joint committee that develops and maintains standards in the IT
industry. 17799 is an international code of practice for information security man-
agement. This section defines confidentiality, integrity and availability controls.
10. ISO/IEC 27034 A standard that provides guidance to help organizations embed security within
their processes that help secure applications running in the environment, includ-
ing application lifecycle processes
1/9
, D487: Secure Software Design
Study online at https://quizlet.com/_hbb0ux
11. Software security a developer with an interest in security who helps amplify the security message at
champion the team level
12. waterfall a sequential, activity-based process in which each phase in the SDLC is performed
methodology sequentially from planning through implementation and maintenance
13. Agile Develop- A software development methodology that delivers functionality in rapid iterations,
ment measured in weeks, requiring frequent communication, development, testing, and
delivery.
14. Scrum an agile project management framework that helps teams structure and manage
their work through a set of values, principles, and practices
15. Daily scrum daily time-boxed event of 15 minutes, or less, for the Development Team to re-plan
the next day of development work during a Sprint. Updates are reflected in the
Sprint Backlog.
16. Sprint review A meeting that occurs after each sprint to show the product or process to stake-
holders for approval and to receive feedback.
17. Sprint retrospec- an opportunity for the Scrum Team to inspect itself and create a plan for improve-
tive ments to be enacted during the next Sprint.
18. Sprint planning A collaborative event in Scrum in which the Scrum team plans the work for the
current sprint.
19. Scrum master A person who ensures that the team is productive, facilitates the daily Scrum,
enables close cooperation across all roles and functions, and removes barriers that
prevent the team from being effective
20. White-box A test where the tester has an in-depth knowledge of the network and systems
being tested, including network diagrams, IP addresses, and even the source code
of custom applications.
2/9
D487: Secure Software Design
ANSWERS (VERIFIED AND WELL ELABORATED ANSWERS) LATEST
Study online at https://quizlet.com/_hbb0ux
UPDATE 2025/2026
1. Building Security A study of real-world software security initiatives organized so that you can deter-
In Maturity Mod- mine where you stand with your software security initiative and how to evolve your
el (BSIMM) efforts over time
2. SAMM offers a roadmap and a well-defined maturity model for secure software develop-
ment and deployment, along with useful tools for self-assessment and planning.
3. Core OpenSAMM Governance
activities Construction
Verification
Deployment
4. static analysis Source code of an application is reviewed manually or with automatic tools without
running the code
5. dynamic analysis Analysis and testing of a program occurs while it is being executed or run
6. Fuzzing Injection of randomized data into a software program in an attempt to find system
failures, memory leaks, error handling issues, and improper input validation
7. OWASP ZAP -Open-source web application security scanner-Can be used as a proxy to manip-
ulate traffic running through it (even https)
8. ISO/IEC 27001 Specifies requirements for establishing, implementing, operating, monitoring,
reviewing, maintaining and improving a documented information security man-
agement system
9. ISO/IEC 17799 ISO/EIC is a joint committee that develops and maintains standards in the IT
industry. 17799 is an international code of practice for information security man-
agement. This section defines confidentiality, integrity and availability controls.
10. ISO/IEC 27034 A standard that provides guidance to help organizations embed security within
their processes that help secure applications running in the environment, includ-
ing application lifecycle processes
1/9
, D487: Secure Software Design
Study online at https://quizlet.com/_hbb0ux
11. Software security a developer with an interest in security who helps amplify the security message at
champion the team level
12. waterfall a sequential, activity-based process in which each phase in the SDLC is performed
methodology sequentially from planning through implementation and maintenance
13. Agile Develop- A software development methodology that delivers functionality in rapid iterations,
ment measured in weeks, requiring frequent communication, development, testing, and
delivery.
14. Scrum an agile project management framework that helps teams structure and manage
their work through a set of values, principles, and practices
15. Daily scrum daily time-boxed event of 15 minutes, or less, for the Development Team to re-plan
the next day of development work during a Sprint. Updates are reflected in the
Sprint Backlog.
16. Sprint review A meeting that occurs after each sprint to show the product or process to stake-
holders for approval and to receive feedback.
17. Sprint retrospec- an opportunity for the Scrum Team to inspect itself and create a plan for improve-
tive ments to be enacted during the next Sprint.
18. Sprint planning A collaborative event in Scrum in which the Scrum team plans the work for the
current sprint.
19. Scrum master A person who ensures that the team is productive, facilitates the daily Scrum,
enables close cooperation across all roles and functions, and removes barriers that
prevent the team from being effective
20. White-box A test where the tester has an in-depth knowledge of the network and systems
being tested, including network diagrams, IP addresses, and even the source code
of custom applications.
2/9